Skip to content

Zero Harbor Security · Atlanta metro, Georgia

Human-Led Penetration Testing

OSCP- and CISSP-certified offensive security, paired with production engineering from inside AWS, a top-ten US bank and a Fortune 500 insurer. A decade each — and you meet all of us.

The deal is signed off. Their security review is the last thing standing. They want a current third-party test with a real name on it. That is the test this firm runs.

$12,000
Fixed fee
10 days
From authorisation
1 retest
Within 30 days

A scanner can tell you what is exposed. It cannot tell you what that is worth.

The findings that stop a deal are rarely a missing patch. They are a permission boundary that holds in the interface and not at the API, or three low-severity issues that chain into one critical. Those need somebody who understands what your system is supposed to do.

5 days end to end

A person tests it. A person signs it.

Tooling runs coverage because it is genuinely better at breadth. The billed hours go into exploitation, chaining findings together, and the access-control and business-logic flaws no scanner models. The attestation carries the name of the operator who did the work.

10 business days, from authorisation

A date your deal can be planned around.

Quoted from signed authorisation rather than from first contact, because scoping and your own legal review are not ours to control. Plenty of firms advertise a turnaround. Almost none put one in the engagement letter.

“Simply running an automated tool does not satisfy the penetration testing requirement… The penetration tester must interpret the results of any automated tools and determine whether additional testing is needed.”
PCI Security Standards Council · Penetration Testing Guidance v1.1 · §4.1

The work

This is what a finding looks like.

Every firm in this market says its testing is thorough. Rather than say it, here is the shape of what gets delivered — the classes that stop enterprise deals, written the way they arrive: a location you can check, an impact stated in business terms, and a rating a reviewer can act on.

Findings summary · illustrative

1 Critical 1 High 1 Medium 1 Low
critical

Tenant isolation bypass in the reporting API

GET /api/v2/reports/{id}

An authenticated user of one tenant could read another tenant’s reports by changing a single identifier. Exploited end to end and reproduced in the report.

high

Password reset token does not expire on use

POST /auth/reset

A token captured from a forwarded email stayed valid indefinitely, allowing account takeover long after the legitimate reset.

medium

Role check enforced in the interface but not at the API

PATCH /api/v2/members/{id}/role

A standard member could grant themselves administrator rights by calling the endpoint directly.

low

Session cookie missing SameSite attribute

Set-Cookie: session

Widens the window for cross-site request forgery where another finding provides the entry point.

Illustrative findings, written to show the format. They are not drawn from any client engagement — work delivered for a client belongs to that client.

What you receive

Four documents, and what each one is for.

A penetration test report is worth exactly what the person reading it will accept — and that person is rarely you. It gets forwarded to an assessor, or to a security reviewer at your customer, who was not in the room and cannot ask you a question.

Executive summary

Forwarded to your prospect’s security lead

One to two pages, written to be sent on without editing. This is the document that moves the deal.

Technical report

Read by your engineers

Every finding with evidence, a severity rating, the business impact and a specific remediation step.

Attestation letter

Filed by their reviewer

One page naming the operator who ran the test, with credentials, scope, method and dates. Usually the exact thing a security review is asking for.

Coverage record

Answers “what did you not test?”

What was checked and how, test by test — including the checks that found nothing. A clean result should still show the work.

How it runs

Ten business days, from the moment you sign.

Not from your first email. Scoping and your own legal review are not ours to control, so the clock starts where our responsibility does.

  1. 1

    Day 0

    Scope agreed, authorisation signed

    The clock starts here, not at your first email.

  2. 2

    Days 1–4

    Testing

    Tooling runs coverage; the hours go into exploitation and chaining.

  3. 3

    Day 5

    Reporting

    Findings written up, rated and evidenced.

  4. 4

    By day 10

    Delivery

    Report, executive summary and attestation letter in your hands.

If the report is late, part of the fee comes back — written into the engagement letter, not just onto this page.

The full scope

Who signs

The name on the report is the person who ran the test.

The common failure in this market is not technical. It is being quoted a senior and delivered a junior, with a report signed by somebody who never touched the system.

Jun 2020 — Dec 2021

Amazon Web Services

Built the end-to-end AWS penetration testing programme — scoping through to executive reporting.

Mar 2019 — Jun 2020

Truist

Infrastructure, application and physical security testing at a top-ten US bank.

Oct 2014 — May 2015

Korean System Assurance

Tested intrusion prevention systems and firewalls to NSS Labs, Tolly Group and ICSA Lab standards, for the Korean government.

These are employers, not clients. The operators and the full record →

When not to

Five reasons not to hire Zero Harbor Security.

Some of these are free alternatives. Naming them costs less than taking an engagement that was never going to help — and if you are weighing whether to put this firm in front of a client of your own, knowing where it is the wrong answer is more useful than another page of claims.

The questionnaire is the whole blocker

If the review wants policies, a SOC 2 report you already hold, or answers to a standard questionnaire, a trust centre closes it faster and cheaper than this.

Your compliance platform already includes testing

Several bundle or broker a test on higher plans. Check what you already own before buying it twice.

The deal closes inside two weeks

Ten business days runs from signed authorisation, and authorisation takes a few days of its own. If your contract signs sooner, this cannot help.

You need continuous coverage

A point-in-time test answers a point-in-time question. If you need always-on scanning, a platform serves you better and we will tell you which.

You are under about twenty-five people

At that size the fee is usually disproportionate to the deal. Ask your reviewer whether a self-assessment plus a remediation commitment clears the gate.

Send the scope, or the date the deal needs to close.

A scoping call within one business day, then a fixed price and a delivery date in writing. If the work is not a fit, we will say so and point you somewhere better.

Start a scoping call